Critical severity9.8NVD Advisory· Published Jul 21, 2023· Updated Jun 17, 2026
CVE-2022-46280
CVE-2022-46280
Description
A use of uninitialized pointer vulnerability exists in the PQS format pFormat functionality of Open Babel 3.1.1 and master commit 530dbfa3. A specially crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
openbabelPyPI | < 3.2.0 | 3.2.0 |
Affected products
5cpe:2.3:a:openbabel:open_babel:3.1.1:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:openbabel:open_babel:3.1.1:*:*:*:*:*:*:*
- (no CPE)range: <=3.1.1
- osv-coords2 versionspkg:rpm/opensuse/openbabel&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/openbabel&distro=openSUSE%20Tumbleweed
< 3.2.0-bp160.1.1+ 1 more
- (no CPE)range: < 3.2.0-bp160.1.1
- (no CPE)range: < 3.2.0-1.1
- Open Babel/Open Babelv5Range: 3.1.1
Patches
Vulnerability mechanics
References
6- talosintelligence.com/vulnerability_reports/TALOS-2022-1670nvdExploitThird Party AdvisoryVendor AdvisoryWEB
- github.com/advisories/GHSA-8qxc-57hf-hc9jghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-46280ghsaADVISORY
- github.com/openbabel/openbabel/commit/2a7d2cda8bd47daade2e555e34b69651a2e132efghsaWEB
- github.com/openbabel/openbabel/security/advisories/GHSA-8qxc-57hf-hc9jghsaWEB
- www.talosintelligence.com/vulnerability_reports/TALOS-2022-1670nvdWEB
News mentions
0No linked articles in our index yet.